Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

PHP Group

First CVE: Apr 17, 1997Active for: 29 yearsTotal CVEs: 777
66.7
VTI Score
TOP TARGET

PHP is a widely embedded server-side scripting language that powers a substantial portion of the web infrastructure, from shared hosting environments to enterprise content management systems, making its vulnerability footprint exceptionally consequential despite a focused product portfolio. Vulnerabilities affecting the PHP interpreter and its standard library skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency to acquire public exploit code. The recurring exposure centers on the core PHP interpreter, the PEAR package manager, and related extensions, clustering around memory-safety issues including out-of-bounds reads, integer overflows, buffer-boundary violations, and improper input validation—flaws typical of a large C codebase handling untrusted user input and complex protocol parsing. Because PHP runs on millions of web servers globally and often lags in patching, defenders should treat PHP interpreter updates as high-priority and track both direct installations and bundled distributions such as FrankenPHP. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
777
Total CVEs
More Total CVEs than 100% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.6%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by PHP Group over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 17, 1997
29 years ago
Most Recent CVE
Jul 3, 2026
23 days ago

Self-Reporting Analysis

Of all the CVEs published by PHP Group as a CNA, 98.9% affect products that PHP Group develops as a vendor.

98.9%
Self-reported: 89 (98.9%)
Third-party: 1 (1.1%)

Of all the CVEs published that affect products developed by PHP Group, 11.5% are self-published by PHP Group as a CNA.

11.5%
88.5%
Self-published: 89 (11.5%)
Other CNAs: 688 (88.5%)

Products(25 total)

Top CVEs

Signals from CVEs in this vendor scope (777 CVEs).

777 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-4577CRITICAL
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows m
Jun 9, 20249.899YESYES
CVE-2012-1823CRITICAL
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign)
May 11, 20129.899YESYES
CVE-2019-11043CRITICAL
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buff
Oct 28, 20199.898YESYES
CVE-2020-28949HIGH
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succe
Nov 19, 20207.895YESYES
CVE-2015-0235HIGH
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code
Jan 28, 201510.092NOYES
CVE-2020-36193HIGH
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.
Jan 18, 20217.591YESNO
CVE-2018-19518HIGH
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of the imap_rimap function in c-client/imap
Nov 25, 20187.590NOYES
CVE-2018-7584CRITICAL
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an HTTP response in the php_stream
Mar 1, 20189.885NOYES
CVE-2011-4885MEDIUM
PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of
Dec 30, 20115.081NOYES
CVE-2005-1921HIGH
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such a
Jul 5, 20057.578NOYES
View all 777 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products777 CVEs
40%
38%
18%
Severity distribution among all CVEs352,719 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local21 (2.7%)
Network320 (41.2%)
Unknown435 (56.0%)
Physical0 (0.0%)
Adjacent Network1 (0.1%)
Attack Complexity
Low318 (40.9%)
High24 (3.1%)
Unknown435 (56.0%)
User Interaction
None297 (38.2%)
Unknown435 (56.0%)
Required45 (5.8%)
Privileges Required
Low21 (2.7%)
High0 (0.0%)
None321 (41.3%)
Unknown435 (56.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (777 CVEs).

CISA KEV
5 CVEs
0.6% of CVEs· 99th percentile
Metasploit
10 CVEs
1.3% of CVEs· 97th percentile
Nuclei
4 CVEs
0.5% of CVEs· 95th percentile
ExploitDB
166 CVEs
21.4% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by PHP Group.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by PHP Group — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For PHP Group's Products

View all 10 CNAs →

Top CWEs